Database/AI/ML frameworks & serving

Weaviate: Crafted entry name with an absolute path
CVSS 7.2CVE-2025-67818AI/ML frameworks & servingcurated
Impact
Crafted entry name with an absolute path → arbitrary file write
Who can reach it
Tenant with data-insert permission
What to do
Upgrade past 1.33.4; data insertion is a filesystem-write primitive
References
Related entries
- Weaviate: RBAC role assignment does not verify the assigner holds the granted permissionsCVE-2026-59093 · WeaviateHigh
- llama.cpp (`gguf_init_from_file`): Use of uninitialized heap variableCVE-2024-32878 · llama.cpp (`gguf_init_from_file`)High
- vLLM (`MediaConnector` SSRF): SSRF via `load_from_url` in multimodal input handlingCVE-2025-6242 · vLLM (`MediaConnector` SSRF)High
- vLLM (`Nemotron_Nano_VL_Config`): RCE via a config class evaluated at model loadCVE-2025-66448 · vLLM (`Nemotron_Nano_VL_Config`)High
- vLLM: remote media is fully materialized before size and per-prompt limits are enforcedCVE-2026-100650 · vLLM (media acquisition layer, audio_url/base64 chat path, batch speech runner, Rust frontend /tokenize)High
- vLLM: overlong token_ids on the disaggregated serving endpoint crash the workerCVE-2026-100651 · vLLM (disaggregated serving endpoint /inference/v1/generate, decoder prompt-length validation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.